Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news
ai

Brex built its AI agent policy by watching what agents actually do, not by writing rules first

Brex's approach to AI agent governance inverts the traditional playbook by deriving policy from observed agent behaviour rather than imposing predetermined rules. The fintech company discovered that conventional guardrails fail when agents require genuine credentials—API keys, OAuth tokens, service accounts—to function in production environments. This empirical methodology reflects a broader industry realisation: agentic frameworks like OpenClaw have achieved adoption at scale, but the security implications remain poorly understood. The gap between what enterprises *think* their agents can do and what they actually do in the wild has become a material risk, with 54% of enterprises already experiencing AI agent incidents, most stemming from overpermissioned credentials and inadequate runtime visibility.

For CX teams currently operating or planning agentic deployments, Brex's experience signals a critical shift in implementation strategy. Rather than designing agent policies in isolation—defining what agents *should* do before deployment—teams need to instrument their environments to capture what agents *are* doing, then build governance retroactively. This creates an uncomfortable tension: agents require real system access to deliver autonomous resolution at scale, yet that same access creates exposure that static rule-based controls cannot adequately contain. The question becomes whether your current stack—whether Zendesk, Salesforce, or Freshdesk—provides sufficient observability and runtime control to support this behaviour-first governance model, or whether you'll need to layer in additional tooling to close the visibility gap.

The implications extend beyond security posture to operational philosophy. Teams accustomed to defining agent capabilities upfront through configuration and rule engines will need to adopt a more iterative, monitoring-driven approach. This demands investment in observability infrastructure and a willingness to constrain agent permissions based on actual usage patterns rather than theoretical threat models. For organisations still evaluating agentic AI adoption, Brex's methodology suggests that the maturity question isn't whether your chosen framework is capable—it's whether your organisation can sustain the operational discipline required to govern agents that operate with real credentials in production systems.